The Superannuation
Cyber and Financial Crime
Coordination Framework
The Superannuation Cyber and Financial Coordination Framework (SC3) is the super sector’s collaboration initiative to protect super fund members from cyber threats, scams and fraud. It brings super funds together to securely share intelligence about emerging threats and plan and respond to growing risks, adding an extra layer of protection to help keep members’ retirement savings and data safe.
How the SC3 works
Communicate
Share threat intelligence
Super funds participating in SC3 securely share information on SuperFCX, an Australian-based secure, superannuation-specific threat-sharing platform.
Coordinate
Plan and respond
SC3 funds work together to prepare for and respond to sector-wide cyber incidents through a shared playbook and simulated incidents.
Collaborate
Work with other stakeholders
Participants work with super sector associations, government, regulators, consumer groups and other sectors including banking to collectively boost protections against cyber and financial crime.
SC3 participating funds represent 75% of superannuation funds under management (non-SMSF).
They come from all parts of the super sector – retail, industry and government funds.
The SC3 is open to all Australian superannuation funds and associations.
Safer super, together.
Cyber threats rarely target a single organisation in isolation. Sharing threat intelligence gives participants earlier visibility of emerging risks, strengthens collective defence, and enables faster, more effective responses to cyber incidents. SuperFCX aligns with the Australian Cyber Security Strategy and with the recommendations of the review of the Security of Critical Infrastructure Act (2018).
A growing threat
Cyber threats facing all financial services including superannuation are increasing in scale, sophistication and frequency. The emergence of AI-enabled threats is accelerating this risk, making phishing, social engineering, fraud and cyber attacks more convincing, scalable and difficult to detect. Stronger collaboration and timely sharing add an additional layer of protection to funds’ own cyber.
The SC3 Framework timeline
2026
SEPT
Super sector cyber incident exercise
Description
FAQs
What services do superannuation funds receive under SC3
SC3 is made up of four pillars: the cyber threat intelligence sharing platform, SuperFCX; a playbook for responding to sector-wide cyber incidents; annual super sector response exercises; and forums and specialist working groups. The specialist working groups are made up of representatives from participating funds, and they contribute to the design of the other three pillars.
Can any super fund join the SC3?
Yes, any APRA-regulated or non-APRA public sector fund is welcome to join SC3 and add an extra layer of protection for their members.
Who is the proposed provider for SuperFCX, the threat intelligence sharing platform?
CI-ISAC Australia is the proposed provider for SuperFCX, pending ACCC final authorisation. It is Australia’s only sovereign, not-for-profit cyber threat intelligence network built exclusively for critical infrastructure and essential services.
Its analysts monitor threats across all 11 critical infrastructure sectors simultaneously, including energy, health, finance, government, telecommunications and more – turning raw data into easily actionable advisories and recommendations.
Members contribute threat intelligence, CI-ISAC analyses and enriches the data and shares it back across the network, anonymously if required. The result is a deep, real-time, Australian-specific threat picture that no single super fund would be able to develop on their own.
It was selected as the most appropriate provider after a thorough evaluation process of several providers against suitability criteria.
Why does the ACCC need to authorise SuperFCX?
Under Australian competition law, entities which are normally in competition with each other, such as super funds, require the authorisation of the Australian Competition and Consumer Commission (ACCC) to jointly procure a service, such as SuperFCX. ASFA applied on behalf of the superannuation sector for this authorisation in March 2026. The ACCC granted interim authorisation on 11 June 2026 and a draft determination on 24 July 2026. The interim authorisation allowed super funds to take preparatory steps to join SuperFCX while waiting for the final determination, which is expected in September/October 2026.
What is ASFA’s role in SC3?
Following reviews of the April 2025 super sector cyber incident, government, regulators and super funds all determined greater collaboration and information sharing was essential. As the sector peak body, ASFA employed a cyber expert to work with the sector, and learn lessons from other industries and jurisdictions to determine what a best-practice approach would look like. The SC3 Framework is the result.
ASFA supports and helps coordinate the SC3 Framework on behalf of the super sector. ASFA does not ‘own’ SC3 – its priorities, activities and direction are determined by its participating funds through the framework’s governance arrangements. ASFA has led and resourced the project phase of the SC3 in its role as the sector peak body, and continues to provide coordination and operational support.
How is SC3 governed?
SC3 is led by the superannuation sector, with its primary governing body being the SC3 Executive Commmittee. This is comprised of fund cyber-responsible executives and is currently co-chaired by Simon Reiter, CareSuper’s Chief Technology Officer and Michael Collins, the SC3 Coordinator.
It has a range of specialist working groups, made up of representatives from participating funds, which have input into the pillars of the SC3. These include working groups for SuperFCX, cyber incident exercises, the Super Sector Cyber Playbook and communications.
Additionally, there are two advisory groups, the Associations Advisory Forum and the Administration and Platform CEO Forum. The Associations Advisory Form provides a formal mechanism for industry associations from across the superannuation sector and related industries to contribute advice, feedback and sector perspectives to the SC3 Framework. The Administration and Platform CEO Forum provides additional strategic advice helping to identify emerging risks, opportunities, and participant needs.
As an ASFA-funded initiative through the pilot and project phase, the ASFA Board currently has responsibility for initial key business and funding decisions.
How are administrators and custodians involved in SC3
Administrators and custodians are primarily involved through their funds, as funds retain responsibility for cyber security. Administrators and custodians take part in the cyber incident exercises. Custodians are represented on the Associations Advisory Forum. Administrators and platform CEOs are consulted and updated through the Administration and Platform CEO Forum.
How do super funds join SC3?
With 75% of super funds (by FUM) so far taking part in SC3, all funds are welcome to join the largest ever collaboration on member protection undertaken by the super sector.
Interested funds should email the SC3 Coordinator.
Participating funds